Skip to main content Skip to footer

How do we score and prioritise impacts, risks and opportunities?

You score impacts on severity, using scale, scope and how hard the impact is to fix if it's negative. Add likelihood for potential impacts. Risks and opportunities are scored on financial magnitude and likelihood. Apply predefined thresholds to decide what's material. Two rules override the default: severity outweighs likelihood for potential human rights impacts, and impacts are assessed gross.

 

Where most scoring methodologies go wrong

Most templates weight severity and likelihood equally. For potential human rights impacts under the ESRS, that's the wrong shape, and it’s not compliant.

Take child labour in the supply chain. A company looks at its own history, its supplier audits and its contracts, and concludes likelihood is low. Score severity and likelihood equally and the impact drops below the threshold and out of the assessment. But child labour is a severe human rights impact, and under the ESRS that severity carries more weight than the low likelihood. Assessed properly it stays material, even though it probably won't happen.

Likelihood only enters the scoring for potential impacts in the first place, which is where the rule bites. Actual impacts are scored on severity alone.

The error sits in the scoring logic rather than in a single conclusion, so every affected topic has to be revisited once it surfaces. And it surfaces during assurance, on a topic auditors treat as high sensitivity.

If your scoring template weights severity and likelihood equally by default, fix the template before the assessment starts.

 

Start from the gross position

Impact materiality always starts from the gross position. You assess the severity of the impact before accounting for any mitigation or prevention measures already in place.

For a negative impact that has already occurred, remediation afterwards has no bearing on whether the impact was material in the first place. The assessment stays anchored to the gross severity of what happened. Remediation actions and their outcomes get disclosed separately.

When scoring potential negative impacts, you may only factor in prevention and mitigation actions if they are already implemented and can reasonably be assumed to effectively reduce severity or likelihood. Stated intentions, planned measures, or policies requiring future implementation cannot be used to reduce the score. If an implemented measure isn't fully operational, the potential impact must be assessed on its full gross position.

A mitigation plan changes how you respond to a risk. It doesn’t remove the need to assess whether the risk is material.

 

Scoring the time horizons


The ESRS asks you to consider impacts across 3 intervals. Short-term is usually your reporting period, so 12 months. Medium-term runs 1 to 5 years. Long-term is anything beyond 5 years.

The time-saver most teams miss is that you assess those horizons together, as a single view, rather than scoring each one separately for every impact. The ESRS supports this directly. You don't have to analyse each time horizon individually unless an impact, risk or opportunity is expected to evolve or change significantly over time.

So the practical question is whether the impact is happening now, and how it might develop over the coming years. Where it stays stable across all 3, one combined assessment covers it. Where it doesn't, split the horizons out and score them separately, and record why you did.

 

The threshold conversation happens first

Set your qualitative and quantitative thresholds before scoring begins, write down the rationale behind each one, and apply them consistently across every IRO. Where judgement was applied, record why and by whom, at the time.

In our experience this is where DMAs fall apart under scrutiny. Different assessors apply different logic to the same criteria, the inconsistencies spread, and there’s no documented rationale to point back to. This can ultimately skew the results. When an auditor starts pulling threads, the team ends up re-justifying decisions that should have been recorded as they were made.

 

What changed under ESRS 2.0

The revised standards, adopted by the European Commission on 3 July 2026 and currently in the scrutiny period with the Parliament and Council, cut mandatory datapoints by 61%. They didn’t simplify scoring. The double materiality framework is intact, both impact and financial materiality are still required, and the methodology is still subject to limited assurance. An auditor examines how you scored, not only what you concluded.

If anything the judgement burden went up. Over-disclosure used to be the safe default. Under ESRS 2.0 it reads as a sign of poor process.

 

Kōan has worked on materiality assessments for 9 years, with companies from listed multinationals to first-time reporters across Europe, Asia and the US. If you want a second pair of eyes on your methodology before your auditor finds the gaps, get in touch.

 

Melina Gkiolma, Sustainability Consultant, Kōan
Published 09 October 2026 · Last reviewed 25 August 2026

 

Melina Gkiolma is a sustainability consultant at Kōan, specialising in CSRD and ESRS. She previously worked at Deloitte Luxembourg and is a One Young World Ambassador.